[oss] Fix blob presigned URL validation when fs.oss.sld.enabled is set - #10230
Conversation
With fs.oss.sld.enabled the shared OSS client signs path-style URLs (host = endpoint host, path = /bucket/key), but validatePresignedUrl always expected a virtual-hosted URL, so every presigned URL request was rejected as an invalid target. Expect the path-style shape when the client configuration has SLD enabled; the default path is unchanged and HTTPS is still required. Generated-by: Claude Code Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Requirement fit: SUPPORTED. Implementation: FINDINGS at [P2] Update the downstream Jindo presigning fixture for the new configuration access
I reproduced the failing Jindo method locally with normal Maven checks. Running the same method with only the presigner implementation restored to the base passes. Please add a The SLD addressing fix has end-to-end value, and its SDK/security contract looks correct. The full |
OSSBlobPresigner.validatePresignedUrl now reads getClientConfiguration().isSLDEnabled(). JindoFileIOTest exercises the same presigner through JindoBlobPresigner, and its Mockito OSSClient left getClientConfiguration() unstubbed, so the call hit a null and failed testCreateBlobPresignedUrlUsesOssClient. Stub it with a default ClientConfiguration, as the OSS fixtures already do. Generated-by: Claude Code Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@JingsongLi Thanks for tracking this down. Fixed — On the new head, Core/integrations JDK 11 is green. On JDK 8, Could you rerun the JDK 8 job when you have a chance? |
|
+1 |
Purpose
fix #10229
fs.oss.sld.enabled=truethe shared OSS client signs path-style URLs (host = endpoint, path =/bucket/key), butOSSBlobPresigner.validatePresignedUrlalways expectedbucket.<endpoint>and/key, so every request failed with "invalid target" (public, internal and PrivateLink endpoints)./bucket/key; bucket, key and HTTPS are still checked. The SLD-off path is unchanged.Tests
OSSFileIOTestcases: path-style URLs on public/internal/PrivateLink endpoints (plus wrong-bucket rejection), and SDK-signed URLs for an encoded key and an endpoint port. All three fail without the fix.getClientConfiguration()in 4 existing mock setups (no assertion changes).mvn -pl paimon-filesystems/paimon-oss-impl clean install(JDK 11) passed:OSSFileIOTest20/20, checkstyle and spotless green.